CVE-2026-33496 | ory oathkeeper up to 26.1.x oauth2_introspection improper validation of unsafe equivalence in input
A vulnerability was found in ory oathkeeper up to 26.1.x. It has been classified as critical. This issue affects the function oauth2_introspection. The manipulation leads to improper validation of unsafe equivalence in input.
This vulnerability is uniquely identified as CVE-2026-33496. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.